HoneyLabs

Akin HTTP request fingerprint

b11cun050_00040017_976354f0

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14618 sends an email when it next hits a sensor.

1.3K

Source IPs

84

Networks

42

Countries

2.9K

Ports hit

18.7K

Events

15

IPs / network

Top networks

Countries

US 962BE 151DE 16GB 15FR 14NL 11IN 11SG 11HK 10CA 7

Ports targeted

What it requests

GET/7.5K
GET/.env96
GET/models65
GET/api/ps65

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.3638 IPs7.9K
python-requests/2.32.5113 IPs3.1K
python-requests/2.34.295 IPs2.2K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.365 IPs1.4K
python-httpx/0.28.141 IPs636
Source IPCCNetwork Last seenEvents
46.16.34.21USAS200019 Alexhost Srl2026-09-08802
207.90.244.28USAS174 Cogent Communications, LLC2026-09-30644
207.90.244.17USAS174 Cogent Communications, LLC2026-09-30628
207.90.244.18USAS174 Cogent Communications, LLC2026-09-30628
207.90.244.19USAS174 Cogent Communications, LLC2026-09-30616
203.175.125.156IDAS139952 PT Trisari Data Indonusa2026-09-22565
207.90.244.26USAS174 Cogent Communications, LLC2026-09-30529
207.90.244.12USAS174 Cogent Communications, LLC2026-09-30502
86.54.31.44CAAS12989 Black HOST Ltd2026-09-30478
160.119.76.210SCAS49870 Alsycon B.V.2026-09-30422
86.54.31.36CAAS12989 Black HOST Ltd2026-09-30413
207.90.244.4USAS174 Cogent Communications, LLC2026-09-29388
207.90.244.6USAS174 Cogent Communications, LLC2026-09-30351
147.139.204.195IDAS45102 Alibaba (US) Technology Co., Ltd.2026-09-10285
71.6.199.23USAS10439 CariNet, Inc.2026-09-30243
49.204.108.155INAS55577 Atria Convergence Technologies Ltd.,2026-09-28243
93.174.95.106NLAS202425 IP Volume inc2026-09-30222
71.6.147.254USAS10439 CariNet, Inc.2026-09-30214
71.6.135.131USAS10439 CariNet, Inc.2026-09-30205
80.82.77.139NLAS202425 IP Volume inc2026-09-30183

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00040017_6b90553bsame header set1.3K IPs9.3Kb11cun050_00040017_e873236csame header set680 IPs6.1Kb11cun050_00040017_eba289fesame header set19 IPs2.8Kb11cun050_00040017_345c845bsame header set469 IPs2.6Kb11cun050_00040017_2015d6b2same header set524 IPs1.2Kb11cun050_00040017_91712619same header set1 IPs960b11cun050_00040017_ee17dab1same header set4 IPs643b11cun050_00040017_588d51acsame header set1 IPs610

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.